Home / Services / Cloud, backup & continuity
Cloud, backup & continuity

Know how long until you can work again

The question after any outage is never “do we have a backup?” It is “how long until the office, the phones and the EMR are working, and how much did we lose?” We manage your cloud, keep its cost honest, and make that answer a number you have tested.

What we do

Keep it running, keep it affordable, prove it can be restored

Microsoft 365 and Azure management

Your cloud accounts set up, secured and watched: subscriptions, identities, storage, and the cloud services your agency relies on, with someone accountable for them.

Cloud cost control

Budgets and alerts on every subscription, unused licenses reclaimed, over-sized services trimmed. Cloud bills drift upward quietly; we make them stop.

Backups that are tested

Microsoft 365 mail and files, laptops and servers backed up to a copy that ransomware cannot reach, with restore tests on a schedule and the result written down.

Disaster recovery planning

What gets restored first, by whom, in what order, and how long each piece takes. Written for the person who is stressed at 7 a.m., not for an auditor.

Downtime procedures

What field staff and the office do when the EMR, the internet or the phones are down: paper forms, a call tree, an on-call number that does not depend on the failed system.

Cloud migration

Moving file shares and old servers into SharePoint, OneDrive and Azure with a plan for permissions, cut-over and a way back.

HIPAA contingency plan

Five required pieces, one plan you can show

The HIPAA Security Rule requires a contingency plan (45 CFR 164.308(a)(7)) so that PHI stays available when something goes wrong. It has five parts. We build each one for your actual systems and keep the evidence.

PartPlain meaningStatus
Data backup planExact copies of PHI exist and can be retrievedRequired
Disaster recovery planHow lost data and systems are restoredRequired
Emergency mode operation planHow you protect PHI and keep working while systems are downRequired
Testing and revisionYou rehearse it and fix what the rehearsal findsAddressable
Applications and data criticalityYou know which systems to restore firstAddressable

“Addressable” does not mean optional: you implement it, or document why an equivalent measure is reasonable.

The two numbers that decide how bad an outage is

How long can you be without it? (the recovery time) and how much work can you afford to lose? (the recovery point). We agree them with you, system by system, then check that your backups and plan really meet them.

SystemYou decide
EMR accessHours without it? Records you can re-enter?
Email and TeamsHours without it?
Phones and call queuesMinutes before patients notice?
Payroll and billing filesHow much recent work is acceptable to redo?
Shared documentsWhich folders are critical?

Microsoft’s retention is not a backup. Deleted or encrypted Microsoft 365 data can be gone for good. A separate backup is what lets you recover.

Restore tests

A backup you have not restored is a hope

  • Regular file-level tests: pick a file, restore it, confirm it opens. We recommend this quarterly.
  • An annual recovery drill: rebuild a key system from backup and time it, so the recovery time is a measurement, not a guess.
  • A written result each time: what was tested, how long it took, what failed, what changed. This is evidence for your compliance file.

What a cloud cost review looks at

  • Licenses assigned to people who have left, or never signed in
  • Plans that include features nobody uses, or miss features you need
  • Azure services running with no owner
  • Storage and backup copies growing without a retention rule
  • A monthly budget and an alert on every subscription, so a surprise bill becomes an email

Find out how long recovery would really take.

We review your backups, your cloud bill and your downtime plan, and give you the recovery time as a number.

Book a continuity review